Privacy Policy
At Nodofact, S.L.U. we process the personal data you provide through this website transparently and for the sole purpose of handling your requests and improving our services. This policy explains what data we collect, why we collect it, who we share it with and what rights you have.
Last updated: July 27, 2026
1. Data controller
The controller of the personal data collected through this website is:
- Registered name
- Nodofact, S.L.U.
- Trading name
- Nodofact
- CIF (tax ID)
- B93819589
- Registered office
- Avenida Pablo Picaso 32, Bloque D, Apartamento 3F, 18008 Granada, España
- legal@nodofact.ai
- Website
- nodofact.ai
- Companies register
- [PENDIENTE / TBC: datos de inscripción en el Registro Mercantil]
You may contact us through any of the channels listed above regarding any matter relating to the processing of your personal data.
2. Personal data we process
We only process data you provide voluntarily, together with data generated automatically while you browse:
- Identification and contact data: name and surname, email address, job title and company, when you request a demo through the website form or write to us by email.
- Request data: the type of demo selected and any additional information you choose to include in your message.
- Browsing data: IP address, device and browser type, pages visited and aggregate usage statistics obtained through cookies and similar technologies, as described in our Cookie Policy.
We do not request or process special categories of personal data (data concerning health, political opinions, trade union membership, ethnic origin, biometric data or others listed in Article 9 GDPR). Please do not provide such information through the website forms.
All fields marked as required in the form are necessary in order to handle your request. If you do not provide them, we will not be able to process it.
3. Purposes and legal bases for processing
We process your personal data for the following purposes, each supported by a legal basis under Article 6 GDPR:
- To manage and respond to your demo or contact request, including sending the confirmation email. Legal basis: steps taken at the request of the data subject prior to entering into a contract (Art. 6(1)(b) GDPR).
- To maintain subsequent commercial contact regarding our products and services, where you have previously approached us. Legal basis: the legitimate interest of Nodofact, S.L.U. in carrying out its business activity (Art. 6(1)(f) GDPR), which you may object to at any time free of charge.
- To produce aggregate website usage statistics in order to improve its content, structure and performance. Legal basis: your consent (Art. 6(1)(a) GDPR), which you may withdraw at any time.
- To comply with legal obligations applicable to our activity, particularly in tax, commercial and data protection matters. Legal basis: compliance with a legal obligation (Art. 6(1)(c) GDPR).
We do not take automated decisions producing legal effects concerning you or similarly significantly affecting you, nor do we carry out profiling for that purpose.
4. Retention periods
We retain your data only for as long as necessary to fulfil the purpose for which it was collected:
- Contact data submitted through the form is retained while your request is handled and, thereafter, for a maximum of three (3) years from the last interaction, unless you ask us to erase it sooner.
- Data processed for statistical purposes is retained for the periods stated in the Cookie Policy.
- Data associated with legal obligations is retained for the limitation periods laid down in the applicable legislation.
Once those periods have elapsed, data is deleted or irreversibly anonymised, without prejudice to it being kept blocked and available to courts, public prosecutors or the competent public authorities for the limitation period of any potential liabilities.
5. Recipients of the data
We do not sell, rent or transfer your personal data to third parties for commercial purposes. In order to provide the service we rely on technology suppliers acting as data processors, with whom we have entered into the agreements required by Article 28 GDPR:
- ActiveCampaign, LLC (Postmark) — United States: sending and delivering the emails generated by the contact form.
- Google Ireland Limited / Google LLC — Ireland and United States: website usage analytics (Google Analytics) and web font delivery (Google Fonts).
- Hosting provider: [PENDIENTE / TBC: proveedor de alojamiento — hosting provider], responsible for hosting and serving the website.
In addition, your data may be disclosed to courts, law enforcement authorities and public administrations where a legal obligation requires it.
6. International data transfers
Some of the suppliers listed above are established outside the European Economic Area or may access the data from the United States. Such international transfers are covered by the appropriate safeguards set out in Chapter V GDPR, in particular the Standard Contractual Clauses approved by the European Commission and, where applicable, the EU-US Data Privacy Framework adequacy decision.
You may request a copy of the safeguards applied by writing to legal@nodofact.ai.
7. Your data protection rights
The law grants you the following rights, which you may exercise free of charge at any time:
- Access: to find out whether we process personal data about you and obtain a copy of it.
- Rectification: to request correction of inaccurate or incomplete data.
- Erasure: to request deletion of your data when it is no longer necessary for the purpose for which it was collected.
- Objection: to object to the processing of your data, including processing based on our legitimate interest.
- Restriction: to request that processing of your data be restricted in the cases provided for by law.
- Portability: to receive your data in a structured, commonly used, machine-readable format, or to request its transmission to another controller.
- Withdrawal of consent: to withdraw consent at any time, without affecting the lawfulness of processing carried out before its withdrawal.
To exercise these rights, send a request to legal@nodofact.ai or to the postal address given in section 1, stating the right you wish to exercise and enclosing a copy of a document proving your identity. We will respond within a maximum of one (1) month, extendable by a further two months in particularly complex cases.
If you believe the processing of your data does not comply with current legislation, or if you are not satisfied with the outcome of exercising your rights, you may lodge a complaint with the competent supervisory authority: the Spanish Data Protection Agency (AEPD), C/ Jorge Juan 6, 28001 Madrid, Spain — www.aepd.es.
8. Information security
We have implemented appropriate technical and organisational measures to ensure a level of security appropriate to the risk, in accordance with Article 32 GDPR, including encryption of communications via TLS, access control based on the principle of least privilege, and the selection of suppliers offering sufficient security guarantees.
That said, no transmission or storage system is entirely infallible. Should a personal data breach occur that is likely to result in a high risk to your rights and freedoms, we will notify you without undue delay, as required by Article 34 GDPR.
9. Minors
This website is aimed exclusively at professionals and organisations and is not intended for children under fourteen (14) years of age. We do not knowingly collect data from children below that age. If we become aware that we have processed a minor's data without the consent of their parents or legal guardians, we will delete it immediately.
10. Changes to this policy
We may update this Privacy Policy to reflect legislative or case-law developments, or changes in the way we provide our services. The version in force will always be the one published on this page, showing its last update date. We recommend reviewing it periodically.
1. Data controller
The controller of the personal data collected through this website is:
- Registered name
- Nodofact, S.L.U.
- Trading name
- Nodofact
- CIF (tax ID)
- B93819589
- Registered office
- Avenida Pablo Picaso 32, Bloque D, Apartamento 3F, 18008 Granada, España
- legal@nodofact.ai
- Website
- nodofact.ai
- Companies register
- [PENDIENTE / TBC: datos de inscripción en el Registro Mercantil]
You may contact us through any of the channels listed above regarding any matter relating to the processing of your personal data.
2. Personal data we process
We only process data you provide voluntarily, together with data generated automatically while you browse:
- Identification and contact data: name and surname, email address, job title and company, when you request a demo through the website form or write to us by email.
- Request data: the type of demo selected and any additional information you choose to include in your message.
- Browsing data: IP address, device and browser type, pages visited and aggregate usage statistics obtained through cookies and similar technologies, as described in our Cookie Policy.
We do not request or process special categories of personal data (data concerning health, political opinions, trade union membership, ethnic origin, biometric data or others listed in Article 9 GDPR). Please do not provide such information through the website forms.
All fields marked as required in the form are necessary in order to handle your request. If you do not provide them, we will not be able to process it.
3. Purposes and legal bases for processing
We process your personal data for the following purposes, each supported by a legal basis under Article 6 GDPR:
- To manage and respond to your demo or contact request, including sending the confirmation email. Legal basis: steps taken at the request of the data subject prior to entering into a contract (Art. 6(1)(b) GDPR).
- To maintain subsequent commercial contact regarding our products and services, where you have previously approached us. Legal basis: the legitimate interest of Nodofact, S.L.U. in carrying out its business activity (Art. 6(1)(f) GDPR), which you may object to at any time free of charge.
- To produce aggregate website usage statistics in order to improve its content, structure and performance. Legal basis: your consent (Art. 6(1)(a) GDPR), which you may withdraw at any time.
- To comply with legal obligations applicable to our activity, particularly in tax, commercial and data protection matters. Legal basis: compliance with a legal obligation (Art. 6(1)(c) GDPR).
We do not take automated decisions producing legal effects concerning you or similarly significantly affecting you, nor do we carry out profiling for that purpose.
4. Retention periods
We retain your data only for as long as necessary to fulfil the purpose for which it was collected:
- Contact data submitted through the form is retained while your request is handled and, thereafter, for a maximum of three (3) years from the last interaction, unless you ask us to erase it sooner.
- Data processed for statistical purposes is retained for the periods stated in the Cookie Policy.
- Data associated with legal obligations is retained for the limitation periods laid down in the applicable legislation.
Once those periods have elapsed, data is deleted or irreversibly anonymised, without prejudice to it being kept blocked and available to courts, public prosecutors or the competent public authorities for the limitation period of any potential liabilities.
5. Recipients of the data
We do not sell, rent or transfer your personal data to third parties for commercial purposes. In order to provide the service we rely on technology suppliers acting as data processors, with whom we have entered into the agreements required by Article 28 GDPR:
- ActiveCampaign, LLC (Postmark) — United States: sending and delivering the emails generated by the contact form.
- Google Ireland Limited / Google LLC — Ireland and United States: website usage analytics (Google Analytics) and web font delivery (Google Fonts).
- Hosting provider: [PENDIENTE / TBC: proveedor de alojamiento — hosting provider], responsible for hosting and serving the website.
In addition, your data may be disclosed to courts, law enforcement authorities and public administrations where a legal obligation requires it.
6. International data transfers
Some of the suppliers listed above are established outside the European Economic Area or may access the data from the United States. Such international transfers are covered by the appropriate safeguards set out in Chapter V GDPR, in particular the Standard Contractual Clauses approved by the European Commission and, where applicable, the EU-US Data Privacy Framework adequacy decision.
You may request a copy of the safeguards applied by writing to legal@nodofact.ai.
7. Your data protection rights
The law grants you the following rights, which you may exercise free of charge at any time:
- Access: to find out whether we process personal data about you and obtain a copy of it.
- Rectification: to request correction of inaccurate or incomplete data.
- Erasure: to request deletion of your data when it is no longer necessary for the purpose for which it was collected.
- Objection: to object to the processing of your data, including processing based on our legitimate interest.
- Restriction: to request that processing of your data be restricted in the cases provided for by law.
- Portability: to receive your data in a structured, commonly used, machine-readable format, or to request its transmission to another controller.
- Withdrawal of consent: to withdraw consent at any time, without affecting the lawfulness of processing carried out before its withdrawal.
To exercise these rights, send a request to legal@nodofact.ai or to the postal address given in section 1, stating the right you wish to exercise and enclosing a copy of a document proving your identity. We will respond within a maximum of one (1) month, extendable by a further two months in particularly complex cases.
If you believe the processing of your data does not comply with current legislation, or if you are not satisfied with the outcome of exercising your rights, you may lodge a complaint with the competent supervisory authority: the Spanish Data Protection Agency (AEPD), C/ Jorge Juan 6, 28001 Madrid, Spain — www.aepd.es.
8. Information security
We have implemented appropriate technical and organisational measures to ensure a level of security appropriate to the risk, in accordance with Article 32 GDPR, including encryption of communications via TLS, access control based on the principle of least privilege, and the selection of suppliers offering sufficient security guarantees.
That said, no transmission or storage system is entirely infallible. Should a personal data breach occur that is likely to result in a high risk to your rights and freedoms, we will notify you without undue delay, as required by Article 34 GDPR.
9. Minors
This website is aimed exclusively at professionals and organisations and is not intended for children under fourteen (14) years of age. We do not knowingly collect data from children below that age. If we become aware that we have processed a minor's data without the consent of their parents or legal guardians, we will delete it immediately.
10. Changes to this policy
We may update this Privacy Policy to reflect legislative or case-law developments, or changes in the way we provide our services. The version in force will always be the one published on this page, showing its last update date. We recommend reviewing it periodically.
1. Data controller
The controller of the personal data collected through this website is:
- Registered name
- Nodofact, S.L.U.
- Trading name
- Nodofact
- CIF (tax ID)
- B93819589
- Registered office
- Avenida Pablo Picaso 32, Bloque D, Apartamento 3F, 18008 Granada, España
- legal@nodofact.ai
- Website
- nodofact.ai
- Companies register
- [PENDIENTE / TBC: datos de inscripción en el Registro Mercantil]
You may contact us through any of the channels listed above regarding any matter relating to the processing of your personal data.
2. Personal data we process
We only process data you provide voluntarily, together with data generated automatically while you browse:
- Identification and contact data: name and surname, email address, job title and company, when you request a demo through the website form or write to us by email.
- Request data: the type of demo selected and any additional information you choose to include in your message.
- Browsing data: IP address, device and browser type, pages visited and aggregate usage statistics obtained through cookies and similar technologies, as described in our Cookie Policy.
We do not request or process special categories of personal data (data concerning health, political opinions, trade union membership, ethnic origin, biometric data or others listed in Article 9 GDPR). Please do not provide such information through the website forms.
All fields marked as required in the form are necessary in order to handle your request. If you do not provide them, we will not be able to process it.
3. Purposes and legal bases for processing
We process your personal data for the following purposes, each supported by a legal basis under Article 6 GDPR:
- To manage and respond to your demo or contact request, including sending the confirmation email. Legal basis: steps taken at the request of the data subject prior to entering into a contract (Art. 6(1)(b) GDPR).
- To maintain subsequent commercial contact regarding our products and services, where you have previously approached us. Legal basis: the legitimate interest of Nodofact, S.L.U. in carrying out its business activity (Art. 6(1)(f) GDPR), which you may object to at any time free of charge.
- To produce aggregate website usage statistics in order to improve its content, structure and performance. Legal basis: your consent (Art. 6(1)(a) GDPR), which you may withdraw at any time.
- To comply with legal obligations applicable to our activity, particularly in tax, commercial and data protection matters. Legal basis: compliance with a legal obligation (Art. 6(1)(c) GDPR).
We do not take automated decisions producing legal effects concerning you or similarly significantly affecting you, nor do we carry out profiling for that purpose.
4. Retention periods
We retain your data only for as long as necessary to fulfil the purpose for which it was collected:
- Contact data submitted through the form is retained while your request is handled and, thereafter, for a maximum of three (3) years from the last interaction, unless you ask us to erase it sooner.
- Data processed for statistical purposes is retained for the periods stated in the Cookie Policy.
- Data associated with legal obligations is retained for the limitation periods laid down in the applicable legislation.
Once those periods have elapsed, data is deleted or irreversibly anonymised, without prejudice to it being kept blocked and available to courts, public prosecutors or the competent public authorities for the limitation period of any potential liabilities.
5. Recipients of the data
We do not sell, rent or transfer your personal data to third parties for commercial purposes. In order to provide the service we rely on technology suppliers acting as data processors, with whom we have entered into the agreements required by Article 28 GDPR:
- ActiveCampaign, LLC (Postmark) — United States: sending and delivering the emails generated by the contact form.
- Google Ireland Limited / Google LLC — Ireland and United States: website usage analytics (Google Analytics) and web font delivery (Google Fonts).
- Hosting provider: [PENDIENTE / TBC: proveedor de alojamiento — hosting provider], responsible for hosting and serving the website.
In addition, your data may be disclosed to courts, law enforcement authorities and public administrations where a legal obligation requires it.
6. International data transfers
Some of the suppliers listed above are established outside the European Economic Area or may access the data from the United States. Such international transfers are covered by the appropriate safeguards set out in Chapter V GDPR, in particular the Standard Contractual Clauses approved by the European Commission and, where applicable, the EU-US Data Privacy Framework adequacy decision.
You may request a copy of the safeguards applied by writing to legal@nodofact.ai.
7. Your data protection rights
The law grants you the following rights, which you may exercise free of charge at any time:
- Access: to find out whether we process personal data about you and obtain a copy of it.
- Rectification: to request correction of inaccurate or incomplete data.
- Erasure: to request deletion of your data when it is no longer necessary for the purpose for which it was collected.
- Objection: to object to the processing of your data, including processing based on our legitimate interest.
- Restriction: to request that processing of your data be restricted in the cases provided for by law.
- Portability: to receive your data in a structured, commonly used, machine-readable format, or to request its transmission to another controller.
- Withdrawal of consent: to withdraw consent at any time, without affecting the lawfulness of processing carried out before its withdrawal.
To exercise these rights, send a request to legal@nodofact.ai or to the postal address given in section 1, stating the right you wish to exercise and enclosing a copy of a document proving your identity. We will respond within a maximum of one (1) month, extendable by a further two months in particularly complex cases.
If you believe the processing of your data does not comply with current legislation, or if you are not satisfied with the outcome of exercising your rights, you may lodge a complaint with the competent supervisory authority: the Spanish Data Protection Agency (AEPD), C/ Jorge Juan 6, 28001 Madrid, Spain — www.aepd.es.
8. Information security
We have implemented appropriate technical and organisational measures to ensure a level of security appropriate to the risk, in accordance with Article 32 GDPR, including encryption of communications via TLS, access control based on the principle of least privilege, and the selection of suppliers offering sufficient security guarantees.
That said, no transmission or storage system is entirely infallible. Should a personal data breach occur that is likely to result in a high risk to your rights and freedoms, we will notify you without undue delay, as required by Article 34 GDPR.
9. Minors
This website is aimed exclusively at professionals and organisations and is not intended for children under fourteen (14) years of age. We do not knowingly collect data from children below that age. If we become aware that we have processed a minor's data without the consent of their parents or legal guardians, we will delete it immediately.
10. Changes to this policy
We may update this Privacy Policy to reflect legislative or case-law developments, or changes in the way we provide our services. The version in force will always be the one published on this page, showing its last update date. We recommend reviewing it periodically.
